Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-69317 2 Scriptsbundle, Wordpress 2 Carspot, Wordpress 2026-01-24 N/A
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle CarSpot carspot allows Reflected XSS.This issue affects CarSpot: from n/a through < 2.4.6.
CVE-2019-15870 1 Scriptsbundle 1 Carspot 2025-03-20 N/A
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.